Releases64
Frequency6 days 15 hours
Last Release
Stars20K
An open-source, code-first Python toolkit for building, evaluating, and deploying sophisticated AI agents with flexibility and control.

CVE History

CVEPublishedCVSS v3CVSS v2

A Code Injection and Missing Authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0.0a1) through 1.28.1 (and 2.0.0a2) on Python (OSS), Cloud Run, and GKE allows an unauthenticated remote attacker to execute arbitrary code on the server hosting the ADK instance. This vulnerability was patched in versions 1.28.1 and 2.0.0a2. Customers need to redeploy the upgraded ADK to their production environments. In addition, if they are running ADK Web locally, they also need to upgrade their local instance.